Skip to main content
Back to Dashboard
Privacy Policy / Privacybeleid

Privacy Policy

Last updated: June 2026 · Version 3.3

1. Data Controller (Verwerkingsverantwoordelijke)

WealthPlannr B.V., registered in the Netherlands (KvK: 42050571).
Contact: privacy@wealthplannr.nl

2. Purpose of Data Processing (Doeleinden)

Data is collected solely for generating your tax evidence reports, portfolio simulations, and financial planning outputs. We process data on the legal basis of contractual necessity (Art. 6(1)(b) GDPR) and, for analytics, legitimate interest (Art. 6(1)(f) GDPR).

3. Data Categories

CategoryExamplesRetention
Account dataEmail, name, user IDUntil account deletion
Financial inputsAsset values, dividends, debtsUntil account deletion
AI-processed documentsBrokerage PDFs, CSVsZero retention (see §4)
Payment dataStripe customer IDPer Stripe retention policy
Technical logsIP address, user agent30 days
Acceptance & consent recordsDocument type/version, timestamp, IP, user agent (proof you agreed)Kept for the statutory limitation period as evidence, beyond the 30-day technical-log window

4. Zero-Retention AI Processing (Transient Processing)

Your financial documents are analyzed in memory by the AI to extract data and are immediately discarded. We do not store uploaded PDFs, CSVs, or their extracted text on any server or database.

  • Documents are sent to the AI model via a secure API call and processed in memory only.
  • Extracted structured data (JSON) is returned to your browser and exists only in your session.
  • We do not use your financial data to train our AI models or the models of our sub-processors (Anthropic).
  • Anthropic's commercial API terms guarantee that input data is not used for model training.

5. Sub-processors (Onderaannemers)

Sub-processorPurposeRegion
Supabase (AWS)Database, authenticationEU-West (Ireland, eu-west-1)
AnthropicAI inference (document extraction)US (no data retention)
NetlifyApplication hosting (functions)EU-West (Ireland, eu-west-1)
StripePayment processingEU (Dublin)
ResendTransactional emailUS
Upstash QStashScheduled job queueUS

6. Data Residency

All personal account data (User ID, email, financial inputs) is stored on EU-based servers (Supabase EU-West region, Ireland / eu-west-1). AI inference calls to Anthropic use their commercial API which guarantees zero data retention and no model training on input data.

International transfers. Some processing involves providers outside the EEA — Anthropic (United States) for AI inference, Resend (United States) for transactional email, Upstash QStash (United States) for scheduled jobs, and Stripe (US parent; EU payments via its Irish entity) for billing. These transfers are safeguarded under GDPR Article 46: Standard Contractual Clauses and/or EU–US Data Privacy Framework certification, per each provider's Data Processing Agreement. All other processing takes place within the EEA.

7. Your Rights (Uw Rechten)

Under the GDPR/AVG, you have the right to:

  • Access (Inzage): Request a copy of all personal data we hold.
  • Rectification (Correctie): Correct inaccurate personal data.
  • Erasure (Vergetelheid): Delete your entire account and all stored data with one click in Settings. This triggers an immediate purge of all stored values (“Right to be Forgotten”).
  • Portability (Overdraagbaarheid): Export your data in a machine-readable format (JSON; CSV for supported reports).
  • Objection (Bezwaar): Object to processing based on legitimate interest.
  • Complaint: File a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

To exercise any right, email privacy@wealthplannr.nl. We respond within 30 days.

8. Security Measures

  • All data encrypted at rest (AES-256) and in transit (TLS 1.3).
  • Row-Level Security (RLS) ensures tenant isolation in the database.
  • API keys are stored server-side only and never exposed to the client.
  • Supabase authentication with bcrypt password hashing.

9. Cookies

CookiePurposeType
wp_state_v5App state (localStorage)Functional
sb-*-auth-tokenSupabase sessionFunctional
stripe_midStripe fraud preventionNecessary

We do not use advertising or tracking cookies.

10. Data Breach Notification

In the event of a personal data breach, WealthPlannr will notify the Autoriteit Persoonsgegevens within 72 hours and affected users without undue delay, in accordance with Art. 33-34 GDPR.

11. Wwft Position

WealthPlannr is not a financial services firm within the meaning of the Wwft (Wet ter voorkoming van witwassen en financieren van terrorisme). We do not provide financial advice, manage assets, or facilitate transactions.

12. Security & Abuse-Prevention Data

To protect the service, other users, and our infrastructure from abuse, we process security-related personal data on the basis of legitimate interest (Art. 6(1)(f) GDPR). This processing is separate from, and retained longer than, the 30-day technical logs described in §3.

  • Categories: IP addresses; device fingerprints/identifiers; HTTP request metadata (headers, paths, query strings, user agents); the content of requests that triggered security controls; timestamps; and geolocation derived from IP.
  • Retention: security logs are retained for the limitation period applicable to the relevant legal claims under Dutch law (typically 5 years for contractual claims under BW 3:310, up to 20 years for tort under BW 3:306).
  • Adversary data: data captured from requests that triggered enforcement actions is not subject to the standard data-minimisation timeline, as it constitutes evidence under Art. 17(3)(e) GDPR.

See our Terms of Service (§7–9) and our Acceptable Use Policy for the conduct rules and enforcement process these logs support.

© 2026 WealthPlannr B.V. · KvK 42050571. WealthPlannr provides financial simulation software and is not a licensed financial advisor under the Wft (Wet op het financieel toezicht). All AI-driven insights are based on 2026 fiscal models and should be verified against official bank statements.
TermsAcceptable UseDPALicenseDashboard